Vulnerability in Linux Kernel Affecting AH6 Routing Header Validation
CVE-2026-80844

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

Badges

πŸ“ˆ Score: 757πŸ‘Ύ Exploit Exists🟑 Public PoC

What is CVE-2026-80844?

CVE-2026-80844 is a vulnerability identified in the Linux kernel that affects the AH6 (Authentication Header for IPv6) routing header validation process. The Linux kernel is the core of many operating systems, providing essential functionality and communication between hardware and software. This particular vulnerability arises when the system improperly handles the "segments_left" value for raw IPv6 HDRINCL packets. Specifically, the assumption that the segments_left value is within expected limits can be violated, leading to an out-of-bounds memory access. This flaw can have severe implications for organizations relying on affected Linux systems, as it opens the door for potential exploitation, impacting system integrity and stability.

Potential impact of CVE-2026-80844

  1. Out-of-Bounds Memory Access: The vulnerability may allow attackers to manipulate pointers, leading to out-of-bounds memory accesses. This can potentially cause instability in the system, including crashes or unexpected behavior of critical services.

  2. Denial of Service (DoS): Exploiting this vulnerability could enable a remote attacker to crash or hang the affected system, resulting in a Denial of Service. This could severely disrupt organizational operations, especially for those relying on uninterrupted network services.

  3. Enhanced Attack Vectors: With an out-of-bounds access, an attacker may find opportunities to leverage this vulnerability to execute arbitrary code or escalate privileges, thereby gaining unauthorized control over the system. This can lead to broader system compromise, data breaches, and further exploitation by advanced persistent threats.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2dc650956e4e163b879b3fb1027f9557abc5c985

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 48b0e36cf54358276ee7aa897034c973097d2bc9

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1b7e066eabcc7d6d8f476c34739b45932f2f4c31

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.